Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

GCP-2026-055

Google Version 1 original

Imported from official source

Published: 2026-08-25Description Description Severity Notes A critical unauthenticated Remote Code Execution (RCE) vulnerability exists in Next.js and libheif when processing malicious image files. Google Cloud infrastructure is not directly vulnerable, but customer workloads running Next.js on Google Cloud (e.g., Cloud Run, GKE, App Engine) may be affected. What should I do? Google Cloud backend services are not directly impacted, and no action is required to secure the underlying Google Cloud infrastructure. However, customers hosting Next.js applications on Google Cloud must take immedia...

This version

Version
1 of 4
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
68a0d3a391f2a83fbffa30e45b647a0a
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.